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A  GAO 

Accountability  Integrity*  Reliability 

Highlights 

Highlights  of  GAO-03-250,  a  report  to  the 
Chairman  and  Ranking  Minority  Member, 
Permanent  Subcommittee  on 
Investigations,  Committee  on 
Governmental  Affairs,  U.S.  Senate 


Why  GAO  Did  This  Study 

Information  technology  (IT)  will 
play  a  critical  role  in  strengthening 
our  nation's  homeland  security 
against  potential  future  attacks. 
Specifically,  IT  will  help  enable  the 
nation  to  identify  potential  threats, 
share  information  more  readily, 
provide  mechanisms  to  protect  our 
homeland,  and  develop  response 
capabilities.  The  Permanent 
Subcommittee  on  Investigations  of 
the  Senate  Committee  on 
Governmental  Affairs  requested  that 
we  identify,  for  fiscal  years  2002  and 
2003,  IT  funding  targeted  for 
purposes  related  to  homeland 
security  in  those  departments  and 
agencies  that  play  a  key  role  in  this 
mission  area  and,  using  our  prior 
work,  report  on  the  IT  management 
issues  facing  these  organizations. 

In  commenting  on  a  draft  of  this 
report,  agencies  provided  technical 
comments  that  were  incorporated  in 
the  report,  as  appropriate. 


www.gao.gov/cgi-bin/getrpt7GAO-03-250. 

To  view  the  full  report,  including  the 
objectives,  scope,  and  methodology,  click  on 
the  link  above.  For  more  information,  contact 
Dave  Powner  at  (202)  512-9286  or 
PownerD  @  gao.gov 


HOMELAND  SECURITY 

Information  Technology  Funding  and 
Associated  Management  Issues 


What  GAO  Found 

We  identified  $2.9  billion  in  IT  funding  for  homeland  security  for  fiscal  year 
2002  and  for  fiscal  year  2003.  For  fiscal  year  2002,  $1.2  billion  of  it  is  for 
organizations  (agencies,  departments,  or  components  of  these)  proposed  to 
move  to  the  Department  of  Homeland  Security.  For  fiscal  year  2003,  $1.7 
billion  is  for  organizations  proposed  to  move  to  the  new  department.  Total 
reported  IT  funding  for  homeland  security  is  likely  understated.  For 
example,  there  may  be  other  potential  costs  that  are  not  reflected  in 
reported  totals,  including  multi-agency  IT  infrastructure  (for  example, 
secure  networks),  new  intelligence  systems,  and  funding  for  existing 
agency  missions  that  appear  to  be  related  to  homeland  security  (for 
example,  Department  of  Defense,  Federal  Aviation  Administration). 

Of  those  organizations  with  significant  IT  funding  that  are  proposed  to 
move  to  the  new  department,  the  FBI’s  National  Infrastructure 
Protection  Center  (NIPC),  the  Immigration  and  Nationalization  Service 
(INS),  the  Coast  Guard,  and  Customs  have  a  large  number  of  GAO 
recommendations  from  our  prior  work  that  still  require  action  (see  figure 
below).  Although  we  did  not  have  specific  open  recommendations  for 
many  of  the  organizations  proposed  to  move  to  the  Department  of 
Homeland  Security,  most  are  from  parent  organizations  that,  based  on 
our  prior  work,  still  face  IT  management  issues.  The  majority  of  open 
recommendations  are  associated  with  securing  information,  having  an 
architecture  or  blueprint  to  guide  system  development  efforts,  managing 
IT  investments,  and  developing  and  acquiring  information  systems.  Since 
September  1996,  we  have  reported  that  poor  information  security  is  a 
widespread  federal  problem  and  therefore  have  designated  it  a 
govemmentwide  high-risk  area. 


Selected  Departments  with  Open  GAO  IT  Recommendations  and  Associated 
Homeland  Security  IT  Funding  Requested  for  Fiscal  Year  2003 

Department  Open  recommendations 

Homeland  security  IT 
funding  (in  millions) 

Treasury  (including  Customs) 

346 

$633.77 

Transportation  (including  Coast 
Guard) 

69 

680.74 

Justice  (including  NIPC,  INS) 

17 

778.95 

Totals 

432 

$2,093.46 

Source:  GAO  and  agency  budget  information  provided  to  GAO. 
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^  G  A  O 

^^^^^^^^Accountability  ★  Integrity  ★  Reliability  _ 

United  States  General  Accounting  Office 
Washington,  D.C.  20548 


December  13,  2002 

The  Honorable  Carl  Levin 
Chairman 

The  Honorable  Susan  Collins 
Ranking  Minority  Member 
Permanent  Subcommittee  on  Investigations 
Committee  on  Governmental  Affairs 
United  States  Senate 

Information  technology  (IT)  will  play  a  critical  role  in  strengthening  our 
nation's  homeland  security  against  potential  future  attacks.  Specifically,  IT 
will  help  enable  the  nation  to  identify  potential  threats,  share  information 
more  readily,  provide  mechanisms  to  protect  our  homeland,  and  develop 
response  capabilities.  As  you  requested,  our  objectives  were  to  identify 
fiscal  years  2002  and  2003  IT  funding  targeted  for  purposes  related  to 
homeland  security  in  those  departments  and  agencies  that  play  a  key  role 
in  this  mission  area  and,  using  our  prior  work,  report  on  the  IT 
management  issues  facing  these  departments  and  agencies. 

To  identify  IT  funding  targeted  for  purposes  related  to  homeland  security  in 
fiscal  years  2002  and  2003,  we  requested  and  reviewed  budget 
documentation  from  each  of  the  24  chief  financial  officer  (CFO) 
departments  and  agencies,  including  their  Exhibit  300s,1  Exhibit  53s,2  and 
other  documents  that  identify  IT  funding  for  homeland  security.  In 
addition,  we  reviewed  the  Office  of  Management  and  Budget’s  (OMB)  June 
2002  Annual  Report  to  Congress  on  Combating  Terrorism  and  the 
President’s  June  2002  report  entitled  The  Department  of  Homeland 
Security. 

To  report  on  the  IT  management  issues  facing  the  24  CFO  departments  and 
agencies,  we  reviewed  GAO  IT  products  for  fiscal  years  1997-2002.  We 
identified  the  recommendations  from  these  products,  which  we  organized 
by  department  or  agency,  and  categorized  them  into  specific  IT  areas  (for 
example,  information  security).  Subsequently,  we  followed  up  on  each 


'Exhibit  300s  are  federal  budget  documents  containing  program  and  project  information 
and  associated  cost,  schedule,  and  performance  information. 

2Exhibit  53s  list  all  of  the  IT  projects  and  their  associated  costs  within  a  federal  organization 
and  are  to  be  prepared  each  year  as  part  of  the  budget  process  in  accordance  with  OMB 
Circular  A-ll. 
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recommendation  to  determine  whether  action  had  been  taken  to  address 
it.3 

On  October  1,  2002,  we  provided  a  briefing  to  your  offices  on  the  results  of 
this  work.4  The  briefing  slides  are  included  as  appendixes  I— III.  As  agreed 
with  your  offices,  the  purpose  of  this  letter  is  to  provide  the  published 
briefing  slides  to  you. 

In  brief,  we  identified  $2.9  billion  in  IT  funding  for  homeland  security  for 
fiscal  year  2002  and  for  fiscal  year  2003.  For  fiscal  year  2002,  $1.2  billion  is 
for  organizations  (agencies,  departments,  or  components  of  these) 
proposed  to  move  to  the  Department  of  Homeland  Security.  For  fiscal  year 
2003,  $1.7  billion  is  for  organizations  proposed  to  move  to  the  new 
department.  However,  total  reported  IT  funding  for  homeland  security  is 
likely  understated,  because  there  may  be  other  potential  costs  that  are  not 
reflected  in  reported  totals,  including  multi-agency  IT  infrastructure  (for 
example,  secure  networks),  new  intelligence  systems,  and  funding  for 
existing  agency  missions  that  appear  to  be  related  to  homeland  security 
(for  example,  Department  of  Defense,  Federal  Aviation  Administration). 
The  majority  of  the  funding  requested  for  fiscal  year  2003  was  reported  by 
the  Department  of  Justice’s  Immigration  and  Naturalization  Service  (INS), 
the  Department  of  Transportation’s  Transportation  Security  Agency,  and 
the  Department  of  the  Treasury’s  United  States  Customs  Service.  Beginning 
with  the  fiscal  year  2004  budget  submission,  agencies  are  to  indicate  in 
Exhibit  53s  whether  IT  projects  are  related  to  homeland  security. 

The  organizations  that  are  proposed  to  move  to  the  new  department  will 
face  IT  management  issues.  Of  those  organizations  with  significant  IT 
funding  that  are  proposed  to  move  to  the  new  department,  the  FBI’s 
National  Infrastructure  Protection  Center,  the  INS,  the  Coast  Guard,  and 
Customs  have  a  large  number  of  GAO  recommendations  that  still  require 
action.  Although  we  did  not  have  specific  open  recommendations  for  many 
of  the  organizations  proposed  to  move  to  the  Department  of  Homeland 
Security,  most  are  from  parent  organizations  that,  based  on  our  prior  work, 
still  face  IT  management  issues.  Of  those  recommendations  that  still 


3Our  approach  focused  on  agencies  and  areas  where  we  have  conducted  IT  reviews  and  was 
not  intended  to  reflect  IT  management  capabilities  across  the  government.  Also,  it  did  not 
include  Inspector  General  reports. 

4We  have  amended  the  briefing  as  of  November  22,  2002,  to  include  minor  changes  and 
technical  updates. 
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require  action,  the  majority  of  open  recommendations  are  associated  with 
securing  information  (information  security),  having  an  architecture  or 
blueprint  to  guide  system  development  efforts  (enterprise  architecture), 
managing  IT  investments  (investment  management),  and  developing  and 
acquiring  information  systems  (systems  development  and  acquisition). 
Since  September  1996,  we  have  reported  that  poor  information  security  is  a 
widespread  federal  problem  and  therefore  have  designated  it  a 
govemmentwide  high-risk  area. 

Agency  Comments 

We  provided  a  draft  of  this  report  to  the  24  CFO  departments  and  agencies 
for  comment.  Several  departments  and  agencies  provided  oral  technical 
comments  that  we  have  incorporated  into  this  report,  as  appropriate. 

As  agreed  with  your  staff,  unless  you  publicly  announce  the  contents  of  this 
report  earlier,  we  plan  no  further  distribution  of  it  until  30  days  from  the 
date  of  this  letter.  At  that  time,  we  will  send  copies  of  this  report  to  other 
interested  congressional  parties.  We  also  will  make  copies  available  to 
others  upon  request.  In  addition,  the  report  will  be  available  at  no  charge 
on  the  GAO  Web  site  at  http://www.gao.gov. 

Should  you  or  your  staff  have  any  questions  on  matters  discussed  in  this 
report,  please  contact  me  at  (202)  512-6408. 1  can  also  be  reached  by  E-mail 
at  WillemssenJ@gao.gov.  Key  contributors  to  this  report  were  Lester 
Diamond,  Joanne  Fiorino,  Robert  Kershaw,  Dave  Powner,  Karl  Seifert, 
Kevin  Secrest,  and  Eric  Winter. 


Joel  C.  Willemssen 

Managing  Director,  Information  Technology  Issues 
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Homeland  Security  IT  Funding  and 
Associated  Management  Issues 
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Briefing  to  the 

Senate  Permanent  Subcommittee  on  Investigations, 
Committee  on  Governmental  Affairs 
October  1 ,  2002 


Note:  We  have  amended  the  briefing  as  of  November  22,  2002,  to  include  minor  changes  and  technical  updates. 
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Overview 


•  Objectives 

•  Scope  and  Methodology 

•  Background 

•  Homeland  Security  Information  Technology  (IT)  Funding 

•  IT  Management  Issues  of  Organizations  Involved  in 
Missions  Related  to  Homeland  Security 
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Objectives 


To  assist  in  oversight  of  homeland  security  IT  spending  for 
organizations  proposed  to  move  to  the  Department  of 
Homeland  Security,  we  were  requested  to 

•  identify  fiscal  years  2002  and  2003  IT  funding  targeted 
for  purposes  relating  to  homeland  security  in 
departments  and  agencies  that  play  a  key  role  in  this 
mission  area,  and 

•  using  prior  work,  report  on  the  IT  management  issues 
facing  these  departments  and  agencies. 
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Scope  and  Methodology 


To  identify  fiscal  years  2002  and  2003  IT  funding  targeted  for  purposes  relating  to 
homeland  security,  we 

•  requested  and  reviewed  budget  documentation  from  each  of  the  24  chief 
financial  officer  (CFO)  agencies,  including  (1)  Exhibit  300s, a  (2)  Exhibit 
53s, b  and  (3)  other  documents  that  identify  homeland  security  IT  funding; 

•  reviewed  (1 )  OMB’s  June  2002  Annual  Report  to  Congress  on  Combating 
Terrorism,  (2)  the  President’s  June  2002  Department  of  Homeland  Security 
report,  and  (3)  OMB’s  memoranda  to  selected  agencies  telling  them  to 
“cease  temporarily”  new  IT  infrastructure  and  business  system  investments 
associated  with  organizations  proposed  to  move  to  the  Department  of 
Homeland  Security. 

•  In  meetings  with  departments  and  agencies,  we  suggested  that  they  use 
the  homeland  security  definition  found  in  OMB’s  June  2002  Annual  Report 
to  Congress  on  Combating  Terrorism  as  a  guideline  when  identifying 
homeland  security  IT  funding. 

aExhibit  300s  are  federal  budget  documents  containing  program  and  project  information  and  associated  cost,  schedule,  and 
performance  information. 

bExhibit  53s  list  all  of  the  IT  projects  and  their  associated  costs  within  a  federal  organization  and  are  to  be  prepared  each  year 
as  part  of  the  budget  process  in  accordance  with  OMB  Circular  A-1 1 . 
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Scope  and  Methodology  (cont’d) 


To  report  on  the  IT  management  issues  facing  the  24  CFOa 
departments  and  agencies,  we 

•  reviewed  GAO  IT  products  for  fiscal  years  1 997-2002; 

•  categorized  the  open  recommendations  by  department  into 
specific  IT  areas  (for  example,  information  security); 

•  followed  up  on  each  open  recommendation  to  see  if  it  had  been 
closed. 

This  approach  focused  on  agencies  or  areas  where  we  have  conducted 
IT  reviews  and  is  not  intended  to  reflect  IT  management  capabilities 
across  the  government.  Also,  it  does  not  include  Inspector  General 
reports. 

We  performed  our  work  in  Washington,  D.C.,  from  July  2002  through 
September  2002,  in  accordance  with  generally  accepted  government 
auditing  standards. 

aThe  CFO  agencies  are  listed  in  appendix  II. 
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Background 


•  The  fiscal  year  2003  President’s  budget  for  governmentwide 
IT  is  about  $52.6  billion,  an  increase  of  8  percent  from  fiscal 
year  2002. a 


•  Fiscal  year  2003  requested  homeland  security  funding  is 
about  $37.8  billion,  an  increase  of  25  percent  from  fiscal 
year  2002. b 


•  22  existing  major  components  are  proposed  by  the 
administration  to  move  to  the  Department  of  Homeland 
Security. 

aFigure  comes  from  OMB’s  Exhibit  53,  Agency  IT  Investments  Portfolio,  June  1 , 2002. 

bFigure  comes  from  the  OMB  Annual  Report  to  Congress  on  Combating  Terrorism,  June  24,  2002,  p.14. 
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Fiscal  Years  2002  ($48.6)  and  2003  ($52.6)  Governmentwide  IT 

Funding 

(in  billions  of  dollars) 

All  Other 
21% 


Defense 

50% 


Transportation 
5% 


Note:  The  percentages  for  these  agencies,  rounded  to  the  nearest  whole  number,  are  approximately  the 
same  for  fiscal  years  2002  and  2003. 


Source:  Exhibit  53s,  June  2002. 


Page  10 


GAO-03-250  Homeland  Security 


Appendix  I 

Homeland  Security  IT  Funding  and 
Associated  Management  Issues 


i 


GAO 

Accountability  *  Integrity  *  Reliability 


Background  (cont’d) 


Homeland  Security  Funding 


FY  2002  Enacted  ($19.6)  and  Emergency  Relief  Fund  ($10.7)a 
(in  billions  of  dollars) 


Treasury 

9% 


Transportation 

19% 


Justice 

24% 


National  security 
21% 


FY  2003  Requests  ($37.8)a 
(in  billions  of  dollars) 


FEMA 


HHS 


All  other 
11% 


Treasury 

8% 


Transportation 
21% 


Justice 

19% 


National  security 
20% 


aThese  figures  do  not  include  funding  for  combating  terrorism  overseas  for  fiscal  years  2002  and  2003,  nor  do  they 
include  August  2002  supplemental  funding. 

Source:  OMB  Annual  Report  to  Congress  on  Combating  Terrorism,  June  24,  2002,  p.14. 
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Background  (cont’d) 


Major  Components  Proposed  by  the  Administration  to  Move  to  the  Department  of  Homeland 
Security  (shaded  boxes  are  proposed  divisions  of  DHS) 


Source:  The  President’s  June  2002  Department  of  Homeland  Security  report.  The  National  Institute  of  Standards  and  Technology’s  Computer  Security  Division  was 
not  included  in  the  President’s  original  proposal,  but  was  incorporated  in  the  President’s  draft  legislation  to  the  Congress. 


Page  12 


GAO-03-250  Homeland  Security 


Appendix  I 

Homeland  Security  IT  Funding  and 
Associated  Management  Issues 
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Accountability  *  Integrity  *  Reliability 

Background  (cont’d) 

Major  Components  Proposed  by  the  Administration  to  Move  to  the  Department  of  Homeland 

Security,  by  Department  or  Agency 

Department  of  Agriculture 

Department  of  Health  and  Human  Services 

•  Animal  and  Plant  Health  Inspection 

•  Civilian  Biodefense  Research  Program 

Service 

•  Chemical,  Biological,  Radiological,  and  Nuclear 

•  Plum  Island  Animal  Disease  Center 

Response  Assets 

Department  of  Commerce 

Department  of  Justice 

•  Critical  Infrastructure  Assurance  Office 

•  Immigration  and  Naturalization  Service 

•  NIST  Computer  Security  Division 

•  National  Infrastructure  Protection  Center 

Department  of  Defense 

•  National  Domestic  Preparedness  Office 

•  National  Communications  System 

•  Office  of  Domestic  Preparedness 

Department  of  Energy 

Department  of  Transportation 

•  Lawrence  Livermore  National  Laboratory 

•  Transportation  Security  Agency 

•  National  Infrastructure  Simulation  and 

•  Coast  Guard 

Analysis  Center 

Department  of  the  Treasury 

•  Nuclear  Incident  Response 

•  Secret  Service 

Federal  Emergency  Management  Agency 

•  Customs  Service 

General  Services  Administration 

New/other  organizations 

•  Federal  Computer  Incident  Response  Center 

•  Domestic  Emergency  Support  Team 

•  Federal  Protective  Service 

•  National  Biological  Warfare  Defense  Analysis  Center 

Source:  The  President’s  June  2002  Department  of  Homeland  Security  report.  The  National  Institute  of  Standards  and  Technology’s  Computer  Security  Division  was 
not  included  in  the  President’s  original  proposal,  but  was  incorporated  in  the  President’s  draft  legislation  to  the  Congress. 

Page  13 


GAO-03-250  Homeland  Security 


Appendix  I 

Homeland  Security  IT  Funding  and 
Associated  Management  Issues 


i 


GAO 

Accountability  *  Integrity  *  Reliability 


Homeland  Security  IT  Funding 


•  We  identified  $2.9  billion  in  enacted  and  requested  homeland  security  IT 
funding  for  both  fiscal  years  2002  and  2003.  For  a  detailed  breakdown  of 
homeland  security  IT  funding  by  CFO  agency,  see  appendix  II. 


•  Twenty-one  organizations  provided  us  with  figures  on  homeland  security 
IT  funding  for  fiscal  years  2002  and  2003;  3  organizations  indicated  that 
they  do  not  have  any  fiscal  years  2002  and  2003  homeland  security  IT 
funding.  We  received  and  incorporated  information  from  the 
Departments  of  Energy  and  Justice  and  the  Environmental  Protection 
Agency  after  the  date  of  this  briefing. 


•  Beginning  with  the  fiscal  year  2004  budget  submission,  agencies  are  to 
indicate  in  Exhibit  53s  whether  IT  projects  are  related  to  homeland 
security. 


•  Organizations  identifying  homeland  security  IT  spending  used  their 
Exhibit  53  or  agency  budget  information  to  respond  to  our  inquiry. 
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Homeland  Security  IT  Funding  (cont’d) 


Estimated  FY  2002  Homeland  Security  IT  Funding, 
by  CFO  Agency  ($2,892)  (in  millions  of  dollars) 


Requested  FY  2003  Homeland  Security  IT  Funding, 
by  CFO  Agency  ($2,934)  (in  millions  of  dollars) 


Federal  Emergency 


Federal  Emergency 
Management 
Agency  ($175) 

Defense  ($45)a 

Other  ($396) 


Health  and  Human 
Services  ($64)b 


Justice  ($779) 


Energy  ($160) 


Transportation 

($681) 


Treasury  ($634) 


aThis  figure  represents  the  amount  Congress  appropriated  for  fiscal  year  2003. 

bHHS’s  fiscal  year  2003  figure  is  significantly  lower  than  that  for  fiscal  year  2002  because  HHS  is  unable  to  determine  its 
level  of  support  for  fiscal  year  2003  until  it  receives  information  from  states  and  localities  to  estimate  their  fiscal  year 
2003  investments. 

Source:  Exhibit  53s  and  other  agency  budget  information. 
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Homeland  Security  IT  Funding  (cont’d) 


FYs  2002  and  2003  Homeland  Security  IT  Funding  for  Components  Proposed  to  Move  to 
the  Department  of  Homeland  Security  (Parent  Organizations  also  Listed)  (cont’d) 

(in  millions  of  dollars) 


Department  or  agency 

FY  2002 

FY  2003 

Health  and  Human  Services 

Civilian  Biodefense  Research  Program 

n/r 

n/r 

Chemical,  Biological,  Radiological,  and  Nuclear  Response  Assets 

n/r 

n/r 

Justice 

Immigration  and  Naturalization  Service 

253.06 

287.39 

National  Infrastructure  Protection  Center 

0.00 

0.00 

Office  of  Domestic  Preparedness 

0.00 

0.00 

Transportation 

Transportation  Security  Agency 

0.00 

643.20 

Coast  Guard 

2.70 

37.54 

Treasury 

Secret  Service 

23.14 

25.70 

Customs  Service 

432.64 

444.70 

New  organizations 

Domestic  Emergency  Support  Team 

n/r 

n/r 

National  Biological  Warfare  Defense  Analysis  Center 

n/r 

n/r 

National  Domestic  Preparedness  Office 

n/r 

n/r 

Total 

$1,150.34 

$1,730.42 

n/r  =  not  reported. 

Source:  Agency  Exhibit  53s  and  agency  budget  information  provided  to  GAO. 
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Homeland  Security  IT  Funding  (cont’d) 


•  Homeland  security  IT  funding  is  likely  understated  because  there  may 
be  other  potential  homeland  security  IT  costs  that  are  not  reflected  in 
reported  totals,  including 


•  multiagency  IT  infrastructure,  including  secure  networks; 

•  The  Department  of  Defense’s  (DOD)  support  for  growing  homeland 
security  role  and  associated  IT  expenditures; 

•  new  intelligence  systems;  and 

•  funding  to  support  existing  agency  missions  (that  is,  DOD,  FAA). 
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IT  Management  Issues 


We  issued  181  GAO  products 
with  IT-related  recommendations 
for  fiscal  years  1 997-2002 
that  contained  1,715 
recommendations,  of  which 

•  789  remain  open  as  of 
August  2002,  and  926 

•  926  are  closed. 


Status  of  Recommendations 


Source:  GAO. 
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IT  Management  Issues  (cont’d) 


Specific  IT  Areas 

•  Our  prior  IT  work  generally  focused  heavily  on  four  major  IT 
areas: 

•  information  security, 

•  enterprise  architecture, 

•  investment  management,  and 

•  systems  development  and  acquisition. 


As  a  result,  most  of  our  open  IT  recommendations  are  in 
these  areas. 

•  We  have  conducted  governmentwide  reviews  in  information 
security  and  architecture. 

•  Other  IT  areas  covered  by  our  prior  recommendations 

included  E-government,  human  capital,  information 
management,  systems  operations,  and 
telecommunications. _ 
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IT  Management  Issues  (cont’d) 


Open  Recommendations,  by  Specific  IT  Areas 


Systems  Development 
(78) 

10% 

Human  Capital  (10) 

1% 

Investment  Managment 
(90) 

11% 

Architecture  (54) 
7% 

E-government  (9) 
1% 

Information  Management 
(32) 

4% 


Systems  Operations  (3) 
0% 


Telecommunications  (4) 
1% 

Other  (8) 

1% 


Information  Security 
(501) 

64% 


Source:  GAO. 
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IT  Management  Issues  (cont’d) 


Information  Security 

•  Since  September  1996,  we  have  (1)  reported  that  poor  information  security  is  a 
widespread  federal  problem  and  (2)  designated  it  a  governmentwide  high-risk 
area. 

•  As  shown  below,  our  latest  analysis  reveals  information  security  weaknesses  for 
the  24  agencies  in  the  6  major  areas  of  general  controls  outlined  in  GAO’s 
criteria  for  performing  information  security  reviews. 


■  Significant  weaknesses  □  Area  not  reviewed  □  No  significant  weaknesses  identified 


Program  Access  Software  Segregation  System  Service 


management  change  of  duties  software  continuity 

Source:  Audit  reports  issued  October  2001  through  October  2002. 
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IT  Management  Issues  (cont’d) 


Enterprise  Architecture  (EA) 

We  reported  in  February  2002,  on  the  basis  of  2001  data,  that  agencies’  use  of 
EAs  (that  is,  blueprints  that  specify  how  agencies  operate  today,  how  they  want  to 
operate  in  the  future,  and  how  they  will  get  there)  is  immature.  Only  4  percent 
reported  having  management  practices  at  framework  stages  4  and  5,  which  are 
described  below. 


Summary  of  Federal  Agencies'  EA  Maturity 


Maturity  stage 


Source:  GAO. 


Maturity  Framework  Stages 

1  Creating  EA  awareness 

^  Building  EA  management 
foundations _ 

3  Developing  architecture 

products _ 

4  Completing  architecture 

products _ 

5  Leveraging  EA  for 
managing  change 
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Open  Recommendations,  by  CFO  Agency3 


Social  Security  Administration 
Small  Business  Administration 
General  Services  Administration13 
Veterans  Affairs 
Treasury13 
Transportation13 
State 
Justice13 
Interior 

Housing  and  Urban  Development 
Health  and  Human  Services13 
Energy13 
Education 
Defense13 
Commerce13 
Agriculture13 

0  50  100  150  200  250  300  350 

Open  recommendations 

aSee  appendix  III  for  a  detailed  breakdown  of  the  open  IT  recommendations  by  specific  IT  area  and  CFO  agency. 
Components  of  these  organizations  have  been  proposed  to  move  into  the  Department  of  Homeland  Security. 

Note:  There  are  77  open  IT  recommendations  not  pertaining  to  the  24  CFO  agencies,  including  38  directed  to  OMB. 

Source:  GAO. 
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IT  Management  Issues  (cont’d) 


Open  IT  Recommendations  for  Components  Proposed  to  Move  to  the  Department 
of  Homeland  Security  (Parent  Organizations  also  Listed) 


Department  or  agency 


Agriculture 

Animal  and  Plant  Health  Inspection  Service 
Plum  Island  Animal  Disease  Center 


Commerce 

Critical  Infrastructure  Assurance  Office 

Computer  Security  Division _ 


Defense 

National  Communications  System _ 

Energy 

Lawrence  Livermore  National  Laboratory 

National  Infrastructure  Simulation  and  Analysis  Center 

Nuclear  Incident  Response _ 


Federal  Emergency  Management  Agenc 


General  Services  Administration 

Federal  Computer  Incident  Response  Center 
Federal  Protective  Service 


Health  and  Human  Services 

Civilian  Biodefense  Research  Program 

Chemical,  Biological,  Radiological,  and  Nuclear  Response  Assets 


Open 

recommendations 


(continued) 
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Open  IT  Recommendations  for  Components  Proposed  to  Move  to  the  Department  of 
Homeland  Security  (Parent  Organizations  also  Listed)  (cont.) 


Department  or  agency 

Open 

recommendations 

Justice 

17 

Immigration  and  Naturalization  Service3 

8 

National  Infrastructure  Protection  Centerb 

8 

Office  of  Domestic  Preparedness 

none 

Transportation 

40 

Transportation  Security  Agency 

none 

Coast  Guard0 

25 

Treasury 

346 

Secret  Service 

none 

Customs  Serviced 

8 

New  Organizations 

none 

Domestic  Emergency  Support  Team 

none 

National  Biological  Warfare  Defense  Analysis  Center 

none 

National  Domestic  Preparedness  Office 

none 

Total 

592 

a3  open  IT  recommendations  in  architecture  and  5  in  investment  management. 
b8  open  IT  recommendations  in  information  security. 


c4  open  IT  recommendations  in  information  security,  4  in  information  management,  1  in  human  capital,  and  16  in  systems  development. 
d6  open  IT  recommendations  in  systems  development,  1  in  architecture,  and  1  in  human  capital. 

Source:  GAO. 
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General  Services  Administration3 
Environmental  Protection  Agency 
Veterans  Affairs 
Treasury3 
State 
Transportation3 
Justice3 
Interior 

Health  and  Human  Services3 
Defense3 
Commerce3 
Agriculture3 
Other  CFO  agencies13 

Closed  IT  recommendations 

Components  of  these  organizations  have  been  proposed  to  move  into  the  Department  of  Homeland  Security. 

bThese  include  8  closed  IT  recommendations  associated  with  the  Social  Security  Administration  and  the  Small  Business 
Administration,  6  with  the  National  Aeronautics  and  Space  Administration,  4  with  the  Department  of  Housing  and  Urban 
Development,  and  3  with  the  Department  of  Education. 

Note:  There  are  92  closed  IT  recommendations  not  pertaining  to  the  24  CFO  agencies,  including  18  directed  to  OMB. 

Source:  GAO. 
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Homeland  Security  IT  Funding, 
by  CFO  Agency 


FY  2002 

FY  2003 

Organization 

(millions  of  dollars) 

Agriculture 

$23.68 

$39.08 

Commerce 

0.04 

0.06 

Defense 

151.19 

45.15 

Education 

3.33 

3.75 

Energy 

171.55 

159.99 

Environmental  Protection  Agency 

0.002 

0.00 

Housing  and  Urban  Development 

0.00 

0.00 

Interior 

3.79 

3.84 

Justice 

1,026.88 

778.95 

Health  and  Human  Services 

386.94 

63.81 

Labor 

13.79 

20.60 

State 

0.00 

104.60 

Veterans  Affairs 

28.01 

32.65 

Agency  for  International  Development 

0.25 

0.39 

(continued) 
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Homeland  Security  IT  Funding, 
by  CFO  Agency  (cont’d) 


FY  2002 

FY  2003 

Organization 

(millions  of  dollars) 

Federal  Emergency  Management  Agency 

234.50 

175.62 

General  Services  Administration 

17.34 

18.29 

Transportation 

2.70 

680.74 

Treasury 

634.46 

633.77 

National  Aeronautics  and  Space  Administrion 

66.00 

50.00 

National  Science  Foundation 

119.17 

115.10 

Nuclear  Regulatory  Commission 

3.93 

1.52 

Office  of  Personnel  Management 

0.00 

0.00 

Small  Business  Adminstration 

0.00 

0.00 

Social  Security  Adminstration 

4.08 

6.03 

Total 

$2,891.63 

$2,933.95 

Source:  Agency  Exhibit  53s  and  agency  budget  information  provided  to  GAO. 
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A  Q  Q  Open  Recommendations,  by  CFO  Agency  (cont’d) 

Accountability  *  Integrity  *  Reliability 

Organization 

Department  of  Education 

Departmentwide 

Total 

2 

2 

1) 

Department  of  Energy 

Office  of  the  Chief  Information 
Officer 

Departmentwide 

Total 

17 

2 

15 

Department  of  Health  and  Human 
Services 

Departmentwide 

Total 

1 

1 

Department  of  the  Interior 

Departmentwide 

Total 

22 

14 

1 

2 

5 

Department  of  Justice 

Immigration  and  Naturalization 
Service 

National  Infrastructure 

Protection  Center 
Departmentwide 

Total 

17 

8 

1 

3 

5 

Department  of  State 

Departmentwide 

Total 

16 

6 

5 

5 

(continued 
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L  A  Open  Recommendations,  by  CFO  Agency 

>JT  W  (cont’d) 

Accountability  *  Integrity  *  Reliability 

Organization  /?  AW  AW  A  /&  / 

Department  of  Transportation 

Federal  Aviation  Administration 

U.S.  Coast  Guard 

Departmentwide 

Total 

40 

2 

4 

10 

4 

3 

1 

16 

Department  of  the  Treasury 

Internal  Revenue  Service 

U.S.  Customs  Service 
Departmentwide 

Total 

346 

318 

9 

1 

3 

2 

1 

6 

6 

Department  of  Veterans  Affairs 

Departmentwide 

Total 

34 

17 

8 

2 

6 

1 

General  Services  Administration 

Departmentwide 

Total 

2 

2 

Social  Security  Administration 

Departmentwide 

Total 

23 

3 

2 

11 

5 

2 

Small  Business  Administration 

Departmentwide 

Total 

19 

1 

2 

1 

1 

13 

1 

Other 

Total 

81 

45 

15 

4 

3 

3 

0 

10 

0 

1 

Grand  total 

Source:  GAO. 

789 

501 

32 

9 

54 

90 

10 

78 

3 

4 

8 

(310005) 
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GAO’s  Mission 

The  General  Accounting  Office,  the  investigative  arm  of  Congress,  exists  to 
support  Congress  in  meeting  its  constitutional  responsibilities  and  to  help  improve 
the  performance  and  accountability  of  the  federal  government  for  the  American 
people.  GAO  examines  the  use  of  public  funds;  evaluates  federal  programs  and 
policies;  and  provides  analyses,  recommendations,  and  other  assistance  to  help 
Congress  make  informed  oversight,  policy,  and  funding  decisions.  GAO’s 
commitment  to  good  government  is  reflected  in  its  core  values  of  accountability, 
integrity,  and  reliability. 

Obtaining  Copies  of 
GAO  Reports  and 
Testimony 

The  fastest  and  easiest  way  to  obtain  copies  of  GAO  documents  at  no  cost  is 
through  the  Internet.  GAO’s  Web  site  (www.gao.gov)  contains  abstracts  and  full- 
text  files  of  current  reports  and  testimony  and  an  expanding  archive  of  older 
products.  The  Web  site  features  a  search  engine  to  help  you  locate  documents 
using  key  words  and  phrases.  You  can  print  these  documents  in  their  entirety, 
including  charts  and  other  graphics. 

Each  day,  GAO  issues  a  list  of  newly  released  reports,  testimony,  and 
correspondence.  GAO  posts  this  list,  known  as  “Today’s  Reports,”  on  its  Web  site 
daily.  The  list  contains  links  to  the  full-text  document  files.  To  have  GAO  e-mail  this 
list  to  you  every  afternoon,  go  to  www.gao.gov  and  select  “Subscribe  to  daily 
E-mail  alert  for  newly  released  products”  under  the  GAO  Reports  heading. 

Order  by  Mail  or  Phone 

The  first  copy  of  each  printed  report  is  free.  Additional  copies  are  $2  each.  A  check 
or  money  order  should  be  made  out  to  the  Superintendent  of  Documents.  GAO 
also  accepts  VISA  and  Mastercard.  Orders  for  100  or  more  copies  mailed  to  a  single 
address  are  discounted  25  percent.  Orders  should  be  sent  to: 

U.S.  General  Accounting  Office 

441  G  Street  NW,  Room  LM 

Washington,  D.C.  20548 

To  order  by  Phone:  Voice:  (202)  512-6000 

TDD:  (202)  512-2537 

Fax:  (202)  512-6061 

To  Report  Fraud, 
Waste,  and  Abuse  in 
Federal  Programs 

Contact: 

Web  site:  www.gao.gov/fraudnet/fraudnet.htm 

E-mail:  fraudnet@gao.gov 

Automated  answering  system:  (800)  424-5454  or  (202)  512-7470 
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